Overview

Affected version

FH1202 V1.2.0.14(408)

Vulnerability details

In FH1202 V1.2.0.14(408), an attacker can obtain the configuration file without authorization through /default.cfg. When making a request to /default.cfg, the attacker can obtain the configuration file default.cfg without authorization. The login password can be found in the decoded file in these parameters.

POC

The default password is 12345678